In the role's Data Scope section:
Properties
Turn off Access to all properties.
Choose how to limit it:
By properties: pick the properties one by one.
By attributes: add rules such as a Fund, a Region, a Property Manager or Same Store. A property has to match every rule you add.
Save the role.
[Image: The "By attributes" tab with a Fund and a Region rule]
A limited scope with no properties and no rules gives no access at all. Users see empty dashboards.
Kinds of data
Turn off Access to all data domains to choose Allowed domains:
PMS: your property management data.
HR_GENERAL and HR_SENSITIVE: people data, if your company has it in UDP.
Data that doesn't belong to a domain is only visible to roles with access to all domains.